Re: [patch 1/1] NetLabel: protect the CIPSOv4 socket option from setsockopt()

2006-10-30 Thread Paul Moore
Eric Paris wrote: > On Mon, 2006-10-30 at 13:03 -0500, [EMAIL PROTECTED] wrote: > >>plain text document attachment (netlabel-sockopts) >>From: Paul Moore <[EMAIL PROTECTED]> >> >>This patch makes two changes to protect applications from either removing or >>tampering with the CIPSOv4 IP option on

Re: [patch 1/1] NetLabel: protect the CIPSOv4 socket option from setsockopt()

2006-10-30 Thread Eric Paris
On Mon, 2006-10-30 at 13:03 -0500, [EMAIL PROTECTED] wrote: > plain text document attachment (netlabel-sockopts) > From: Paul Moore <[EMAIL PROTECTED]> > > This patch makes two changes to protect applications from either removing or > tampering with the CIPSOv4 IP option on a socket. The first is

Re: [patch 1/1] NetLabel: protect the CIPSOv4 socket option from setsockopt()

2006-10-30 Thread James Morris
On Mon, 30 Oct 2006, [EMAIL PROTECTED] wrote: > From: Paul Moore <[EMAIL PROTECTED]> > > This patch makes two changes to protect applications from either removing or > tampering with the CIPSOv4 IP option on a socket. Thanks. Applied to: git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/s

[patch 1/1] NetLabel: protect the CIPSOv4 socket option from setsockopt()

2006-10-30 Thread paul . moore
From: Paul Moore <[EMAIL PROTECTED]> This patch makes two changes to protect applications from either removing or tampering with the CIPSOv4 IP option on a socket. The first is the requirement that applications have the CAP_NET_RAW capability to set an IPOPT_CIPSO option on a socket; this prevent